Bug #77669 [NEW]: A crash in zend_mm_alloc_small
| From: | profic at gmail dot com | Date: | Mon, 25 Feb 2019 22:20:12 +0000 |
| Subject: | Bug #77669 [NEW]: A crash in zend_mm_alloc_small | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-219734@lists.php.net to get a copy of this message | ||
From: profic at gmail dot com
Operating system: Ubuntu 18.04
PHP version: 7.2.15
Package: Reproducible crash
Bug Type: Bug
Bug description:A crash in zend_mm_alloc_small
Description:
------------
I've looked through other similar bugs, but haven't found the exact
match. However the main thing is the same: a crash inside
zend_mm_alloc_small() when a rather large code base is used/ Trying to
extract the offending stuff seems impossible as even the count of
retured from a database rows is relevant. (In my case it is distinct:
the difference between a crash and a non-crash lays between n and n+1
returned rows from the db.) Thus all I have is two backtraces.
Actual result:
--------------
1) This one is using a plus operator with arrays:
Program received signal SIGSEGV, Segmentation fault.
zend_mm_alloc_small (bin_num=6, size=56, heap=0x7f89d4400040) at
./Zend/zend_alloc.c:1273
1273 ./Zend/zend_alloc.c: No such file or directory.
(gdb) bt full
#0 zend_mm_alloc_small (bin_num=6, size=56, heap=0x7f89d4400040) at
./Zend/zend_alloc.c:1273
p = 0x7f89d44ff7a800
#1 _emalloc_56 () at ./Zend/zend_alloc.c:2352
No locals.
#2 0x0000556371c55ec2 in zend_array_dup (source=0x7f89d4466540) at
./Zend/zend_hash.c:1764
idx = <optimized out>
target = <optimized out>
#3 0x0000556371c40b8d in _zval_copy_ctor_func
(zvalue=zvalue@entry=0x7f89d441f1e0) at ./Zend/zend_variables.c:169
__z = 0x7f89d441f1e0
#4 0x0000556371c3cce0 in add_function (result=0x7f89d441f1e0,
op1=0x7f89d441f0e0, op2=op2@entry=0x7f89d441f1d0)
at ./Zend/zend_operators.c:925
_z1 = 0x7f89d441f1e0
_z2 = 0x7f89d441f0e0
_gc = <optimized out>
_t = <optimized out>
op1_copy = {value = {lval = 140229948686560, dval =
6.9282800164110129e-310, counted = 0x7f89d44740e0,
str = 0x7f89d44740e0, arr = 0x7f89d44740e0, obj =
0x7f89d44740e0, res = 0x7f89d44740e0, ref = 0x7f89d44740e0,
ast = 0x7f89d44740e0, zv = 0x7f89d44740e0, ptr =
0x7f89d44740e0, ce = 0x7f89d44740e0, func = 0x7f89d44740e0,
ww = {w1 = 3561439456, w2 = 32649}}, u1 = {v = {type = 0
'\000', type_flags = 242 '\362', const_flags = 65 'A',
reserved = 212 '\324'}, type_info = 3561091584}, u2 =
{next = 32649, cache_slot = 32649, lineno = 32649,
num_args = 32649, fe_pos = 32649, fe_iter_idx = 32649,
access_flags = 32649, property_guard = 32649,
extra = 32649}}
op2_copy = {value = {lval = 140229948337920, dval =
6.9282799991859082e-310, counted = 0x7f89d441ef00,
str = 0x7f89d441ef00, arr = 0x7f89d441ef00, obj =
0x7f89d441ef00, res = 0x7f89d441ef00, ref = 0x7f89d441ef00,
ast = 0x7f89d441ef00, zv = 0x7f89d441ef00, ptr =
0x7f89d441ef00, ce = 0x7f89d441ef00, func = 0x7f89d441ef00,
ww = {w1 = 3561090816, w2 = 32649}}, u1 = {v = {type = 106
'j', type_flags = 204 '\314',
const_flags = 200 '\310', reserved = 113 'q'}, type_info =
1908984938}, u2 = {next = 21859,
cache_slot = 21859, lineno = 21859, num_args = 21859, fe_pos
= 21859, fe_iter_idx = 21859,
access_flags = 21859, property_guard = 21859, extra =
21859}}
converted = <optimized out>
#5 0x0000556371caa021 in ZEND_ADD_SPEC_CV_TMPVAR_HANDLER () at
./Zend/zend_vm_execute.h:44848
free_op2 = 0x7f89d441f1d0
op1 = <optimized out>
op2 = <optimized out>
result = <optimized out>
#6 0x0000556371cee8a4 in execute_ex (ex=0x7f89d4400040) at
./Zend/zend_vm_execute.h:62846
orig_opline = <optimized out>
orig_execute_data = <optimized out>
#7 0x0000556371cf43a7 in zend_execute
(op_array=op_array@entry=0x7f89d44740e0,
return_value=return_value@entry=0x7f89d4498ac0) at
./Zend/zend_vm_execute.h:63776
execute_data = <optimized out>
#8 0x0000556371c42d92 in zend_execute_scripts (type=type@entry=8,
retval=0x7f89d4498ac0, retval@entry=0x7ffc4d7e7740,
file_count=-733876096, file_count@entry=1) at ./Zend/zend.c:1498
files = {{gp_offset = 32, fp_offset = 0, overflow_arg_area =
0x7ffc4d7e6710, reg_save_area = 0x7ffc4d7e66a0}}
i = 0
file_handle = 0x7ffc4d7e7750
op_array = 0x7f89d44740e0
#9 0x0000556371cfcd5a in php_cli_server_dispatch_router
(client=0x5563733a6c20, server=<optimized out>)
at ./sapi/cli/php_cli_server.c:2117
retval = {value = {lval = 93885623332104, dval =
4.6385661126783968e-310, counted = 0x5563733a6d08,
str = 0x5563733a6d08, arr = 0x5563733a6d08, obj =
0x5563733a6d08, res = 0x5563733a6d08, ref = 0x5563733a6d08,
ast = 0x5563733a6d08, zv = 0x5563733a6d08, ptr =
0x5563733a6d08, ce = 0x5563733a6d08, func = 0x5563733a6d08,
ww = {w1 = 1933208840, w2 = 21859}}, u1 = {v = {type = 0
'\000', type_flags = 0 '\000', const_flags = 0 '\000',
reserved = 0 '\000'}, type_info = 0}, u2 = {next = 21859,
cache_slot = 21859, lineno = 21859,
num_args = 21859, fe_pos = 21859, fe_iter_idx = 21859,
access_flags = 21859, property_guard = 21859,
extra = 21859}}
__orig_bailout = 0x7ffc4d7e8bf0
__bailout = {{__jmpbuf = {93885603123128, 84926004876533906,
93885603122568, 1, 93885623332104, 93885623331872,
84926004857659538, 6058413123358548114}, __mask_was_saved
= 0, __saved_mask = {__val = {93885598456025, 1,
93885621682208, 93885603123152, 7713376935073365248, 1,
93885622513304, 93885603123152, 93885603122568, 1,
0, 93885621682208, 93885599559546, 93885621682208,
7713376935073365248, 93885603122560}}}}
decline = 0
zfd = {handle = {fd = -733528064, fp = 0x7f89d4474000, stream =
{handle = 0x7f89d4474000, isatty = 0, mmap = {
len = 9346, pos = 0, map = 0x0,
buf = 0x7f89d90f4000 <error: Cannot access memory at
address 0x7f89d90f4000>, old_handle = 0x0,
old_closer = 0x0}, reader = 0x556371bf52f0
<_php_stream_read>,
fsizer = 0x556371bdbac0 <php_zend_stream_fsizer>, closer =
0x556371bdbaa0 <php_zend_stream_mmap_closer>}},
filename = 0x556373392350 "index.php", opened_path = 0x0, type
= ZEND_HANDLE_MAPPED, free_filename = 0 '\000'}
old_cwd = 0x7ffc4d7e6710 "/srv/zags-broadcast/web"
#10 0x0000556371cfd74b in php_cli_server_dispatch
(client=0x5563733a6c20, server=0x556372060d80 <server>)
at ./sapi/cli/php_cli_server.c:2156
is_static_file = <optimized out>
is_static_file = <optimized out>
send_header_func = 0x556371cfd2a0
<sapi_cli_server_send_headers>
#11 php_cli_server_recv_event_read_request (server=0x556372060d80
<server>, client=0x5563733a6c20)
at ./sapi/cli/php_cli_server.c:2379
errstr = 0x0
status = <optimized out>
#12 0x0000556371cfde40 in php_cli_server_do_event_for_each_fd_callback
(_params=_params@entry=0x7ffc4d7e7a30,
fd=<optimized out>, event=event@entry=1) at
./sapi/cli/php_cli_server.c:2462
client = <optimized out>
params = 0x7ffc4d7e7a30
server = 0x556372060d80 <server>
#13 0x0000556371cfec0e in php_cli_server_poller_iter_on_active
(poller=0x556372060d88 <server+8>,
callback=0x556371cfddf0
<php_cli_server_do_event_for_each_fd_callback>, opaque=0x7ffc4d7e7a30)
at ./sapi/cli/php_cli_server.c:846
retval = <optimized out>
fd = <optimized out>
max_fd = <optimized out>
retval = <optimized out>
fd = <optimized out>
max_fd = <optimized out>
__d = <optimized out>
__d = <optimized out>
#14 php_cli_server_do_event_for_each_fd (whandler=0x556371cfbe10
<php_cli_server_send_event>,
rhandler=0x556371cfd590 <php_cli_server_recv_event_read_request>,
server=0x556372060d80 <server>)
at ./sapi/cli/php_cli_server.c:2480
params = {server = 0x556372060d80 <server>, rhandler =
0x556371cfd590 <php_cli_server_recv_event_read_request>,
whandler = 0x556371cfbe10 <php_cli_server_send_event>}
params = <optimized out>
#15 php_cli_server_do_event_loop (server=0x556372060d80 <server>) at
./sapi/cli/php_cli_server.c:2490
tv = {tv_sec = 0, tv_usec = 995055}
n = <optimized out>
retval = <optimized out>
retval = <optimized out>
tv = <optimized out>
n = <optimized out>
err = <optimized out>
errstr = <optimized out>
#16 do_cli_server (argc=<optimized out>, argv=<optimized out>) at
./sapi/cli/php_cli_server.c:2612
php_optarg = 0x5563731f87e0 "0.0.0.0:8081"
php_optind = 3
c = <optimized out>
server_bind_address = <optimized out>
document_root = <optimized out>
router = <optimized out>
document_root_buf =
"/srv/zags-broadcast/web\000\000\200!\000\000\000\000\000xq!\000\000\000\000\000\060t!\000\000\000\000\000\000`\001\000\000\000\000\000\003\000\000\000\211\177\000\000\000~~M\374\177\000\000\300{~M\374\177\000\000\350~~M\374\177\000\000\002\000\000\000\000\000\000\000\001\312\000\000\000\000\000\000\255n\355Ø\177",
'\000' <repeats 11 times>,
"\200\232\001\000\000\000\000\324{\232\001\000\000\000\000\324{\232\001",
'\000' <repeats 12 times>,
"\005\000\000\000\211\177\000\000\000p\272\001\000\000\000\000\000\220\272\001\000\000\000\000\b\200\272\001\000\000\000\000\020\200\272\001\000\000\000\000\000p\232\001\000\000\000\000\221"...
#17 0x0000556371a8c4d2 in main (argc=4, argv=0x5563731f8770) at
./sapi/cli/php_cli.c:1406
__orig_bailout = 0x0
__bailout = {{__jmpbuf = {93885603034400, -84111279872286574, 0,
140721608625124, 0, 140721608625128,
84926009819521170, 6058412891705565330}, __mask_was_saved
= 0, __saved_mask = {__val = {17179869188,
140229998027808, 140229998027808, 0 <repeats 12 times>,
1}}}}
c = <optimized out>
exit_status = 0
module_started = 1
sapi_started = 1
php_optarg = 0x5563731f87e0 "0.0.0.0:8081"
php_optind = 3
use_extended_info = 0
ini_path_override = 0x0
ini_entries = 0x0
ini_entries_len = 0
ini_ignore = 0
sapi_module = <optimized out>
(gdb)
2) And this one is a result of replacing the plus array operator with an
array_merge() call in the attempt to mitigate the problem:
Program received signal SIGSEGV, Segmentation fault.
zend_mm_alloc_small (bin_num=6, size=56, heap=0x7f0ffc400040) at
./Zend/zend_alloc.c:1273
1273 ./Zend/zend_alloc.c: No such file or directory.
(gdb) bt full
#0 zend_mm_alloc_small (bin_num=6, size=56, heap=0x7f0ffc400040) at
./Zend/zend_alloc.c:1273
p = 0x7f0ffc50093000
#1 _emalloc_56 () at ./Zend/zend_alloc.c:2352
No locals.
#2 0x000055f6a0a92ec2 in zend_array_dup (source=0x7f0ffc467578) at
./Zend/zend_hash.c:1764
idx = <optimized out>
target = <optimized out>
#3 0x000055f6a0b11df0 in
ZEND_ASSIGN_DIM_SPEC_CV_TMPVAR_OP_DATA_VAR_HANDLER () at
./Zend/zend_vm_execute.h:47298
__z = 0x7f0ffc41fc70
_zv = 0x7f0ffc41fc70
_arr = <optimized out>
object_ptr = 0x7f0ffc41fc70
free_op2 = <optimized out>
free_op_data = <optimized out>
value = <optimized out>
variable_ptr = <optimized out>
dim = <optimized out>
#4 0x000055f6a0b2a77e in execute_ex (ex=0x7f0ffc400040) at
./Zend/zend_vm_execute.h:63077
orig_opline = <optimized out>
orig_execute_data = <optimized out>
#5 0x000055f6a0b313a7 in zend_execute
(op_array=op_array@entry=0x7f0ffc4740e0,
return_value=return_value@entry=0x7f0ffc4989a0) at
./Zend/zend_vm_execute.h:63776
execute_data = <optimized out>
#6 0x000055f6a0a7fd92 in zend_execute_scripts (type=type@entry=8,
retval=0x7f0ffc4989a0, retval@entry=0x7fff3301d3d0,
file_count=-62784512, file_count@entry=1) at ./Zend/zend.c:1498
files = {{gp_offset = 32, fp_offset = 8, overflow_arg_area =
0x7fff3301c3a0, reg_save_area = 0x7fff3301c330}}
i = 0
file_handle = 0x7fff3301d3e0
op_array = 0x7f0ffc4740e0
#7 0x000055f6a0b39d5a in php_cli_server_dispatch_router
(client=0x55f6a19c4020, server=<optimized out>)
at ./sapi/cli/php_cli_server.c:2117
retval = {value = {lval = 94517761687816, dval =
4.6697978971759841e-310, counted = 0x55f6a19c4108,
str = 0x55f6a19c4108, arr = 0x55f6a19c4108, obj =
0x55f6a19c4108, res = 0x55f6a19c4108, ref = 0x55f6a19c4108,
ast = 0x55f6a19c4108, zv = 0x55f6a19c4108, ptr =
0x55f6a19c4108, ce = 0x55f6a19c4108, func = 0x55f6a19c4108,
ww = {w1 = 2711372040, w2 = 22006}}, u1 = {v = {type = 0
'\000', type_flags = 0 '\000', const_flags = 0 '\000',
reserved = 0 '\000'}, type_info = 0}, u2 = {next = 22006,
cache_slot = 22006, lineno = 22006,
num_args = 22006, fe_pos = 22006, fe_iter_idx = 22006,
access_flags = 22006, property_guard = 22006,
extra = 22006}}
__orig_bailout = 0x7fff3301e880
__bailout = {{__jmpbuf = {94517749997496, -5842525765454173790,
94517749996936, 1, 94517761687816, 94517761687584,
-5842525765938615902, -362528079560873566},
__mask_was_saved = 0, __saved_mask = {__val = {94517745330393,
140734049146736, 140734049146336, 140734049146736,
94517749997064, 140734049146560, 139706680025055,
206158430256, 140734049146320, 0, 15, 8589934592,
94517746433768, 32, 17432682182253752064,
94517749996928}}}}
decline = 0
zfd = {handle = {fd = -62439424, fp = 0x7f0ffc474000, stream =
{handle = 0x7f0ffc474000, isatty = 0, mmap = {
len = 9346, pos = 0, map = 0x0,
buf = 0x7f100118b000 <error: Cannot access memory at
address 0x7f100118b000>, old_handle = 0x0,
old_closer = 0x0}, reader = 0x55f6a0a322f0
<_php_stream_read>,
fsizer = 0x55f6a0a18ac0 <php_zend_stream_fsizer>, closer =
0x55f6a0a18aa0 <php_zend_stream_mmap_closer>}},
filename = 0x55f6a1b42350 "index.php", opened_path = 0x0, type
= ZEND_HANDLE_MAPPED, free_filename = 0 '\000'}
old_cwd = 0x7fff3301c3a0 "/srv/zags-broadcast/web"
#8 0x000055f6a0b3a74b in php_cli_server_dispatch
(client=0x55f6a19c4020, server=0x55f6a0e9dd80 <server>)
at ./sapi/cli/php_cli_server.c:2156
is_static_file = <optimized out>
is_static_file = <optimized out>
send_header_func = 0x0
#9 php_cli_server_recv_event_read_request (server=0x55f6a0e9dd80
<server>, client=0x55f6a19c4020)
at ./sapi/cli/php_cli_server.c:2379
errstr = 0x0
status = <optimized out>
#10 0x000055f6a0b3ae40 in php_cli_server_do_event_for_each_fd_callback
(_params=_params@entry=0x7fff3301d6c0,
fd=<optimized out>, event=event@entry=1) at
./sapi/cli/php_cli_server.c:2462
client = <optimized out>
params = 0x7fff3301d6c0
server = 0x55f6a0e9dd80 <server>
#11 0x000055f6a0b3bc0e in php_cli_server_poller_iter_on_active
(poller=0x55f6a0e9dd88 <server+8>,
callback=0x55f6a0b3adf0
<php_cli_server_do_event_for_each_fd_callback>, opaque=0x7fff3301d6c0)
at ./sapi/cli/php_cli_server.c:846
retval = <optimized out>
fd = <optimized out>
max_fd = <optimized out>
retval = <optimized out>
fd = <optimized out>
max_fd = <optimized out>
__d = <optimized out>
__d = <optimized out>
#12 php_cli_server_do_event_for_each_fd (whandler=0x55f6a0b38e10
<php_cli_server_send_event>,
rhandler=0x55f6a0b3a590 <php_cli_server_recv_event_read_request>,
server=0x55f6a0e9dd80 <server>)
at ./sapi/cli/php_cli_server.c:2480
params = {server = 0x55f6a0e9dd80 <server>, rhandler =
0x55f6a0b3a590 <php_cli_server_recv_event_read_request>,
whandler = 0x55f6a0b38e10 <php_cli_server_send_event>}
params = <optimized out>
#13 php_cli_server_do_event_loop (server=0x55f6a0e9dd80 <server>) at
./sapi/cli/php_cli_server.c:2490
tv = {tv_sec = 0, tv_usec = 996211}
n = <optimized out>
retval = <optimized out>
retval = <optimized out>
tv = <optimized out>
n = <optimized out>
err = <optimized out>
errstr = <optimized out>
#14 do_cli_server (argc=<optimized out>, argv=<optimized out>) at
./sapi/cli/php_cli_server.c:2612
php_optarg = 0x55f6a19a87e0 "0.0.0.0:8081"
php_optind = 3
c = <optimized out>
server_bind_address = <optimized out>
document_root = <optimized out>
router = <optimized out>
document_root_buf =
"/srv/zags-broadcast/web\000\000\200!\000\000\000\000\000xq!\000\000\000\000\000\060t!\000\000\000\000\000\000`\001\000\000\000\000\000\003\000\000\000\020\177\000\000\220\332\001\063\377\177\000\000P\330\001\063\377\177\000\000x\333\001\063\377\177\000\000\002\000\000\000\000\000\000\000\001\312\000\000\000\000\000\000\255\336\366\000\020\177",
'\000' <repeats 11 times>,
"\200\232\001\000\000\000\000\324{\232\001\000\000\000\000\324{\232\001",
'\000' <repeats 12 times>,
"\005\000\000\000\020\177\000\000\000p\272\001\000\000\000\000\000\220\272\001\000\000\000\000\b\200\272\001\000\000\000\000\020\200\272\001\000\000\000\000\000p\232\001\000\000\000\000"...
#15 0x000055f6a08c94d2 in main (argc=4, argv=0x55f6a19a8770) at
./sapi/cli/php_cli.c:1406
__orig_bailout = 0x0
__bailout = {{__jmpbuf = {94517749908768, 5842659409073367458,
0, 140734049151092, 0, 140734049151096,
-5842525767226267230, -362527813012330078},
__mask_was_saved = 0, __saved_mask = {__val = {17179869188,
139706683724832, 139706683724832, 0 <repeats 12 times>,
1}}}}
c = <optimized out>
exit_status = 0
module_started = 1
sapi_started = 1
php_optarg = 0x55f6a19a87e0 "0.0.0.0:8081"
php_optind = 3
use_extended_info = 0
ini_path_override = 0x0
ini_entries = 0x0
ini_entries_len = 0
ini_ignore = 0
sapi_module = <optimized out>
(gdb)
If there is something else I can provide, I'm open to suggestions.
--
Edit bug report at https://bugs.php.net/bug.php?id=77669&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=77669&r=trysnapshot54
Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=77669&r=trysnapshot55
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=77669&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=77669&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=77669&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=77669&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=77669&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=77669&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=77669&r=support
Expected behavior: https://bugs.php.net/fix.php?id=77669&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=77669&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=77669&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=77669&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=77669&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=77669&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=77669&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=77669&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=77669&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=77669&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=77669&r=mysqlcfg